Jon Williams

@br4inde4d.bsky.social

Vulnerability Researcher at Bishop Fox

Sometimes a DoS really is just a DoS! Here's a look behind the curtain at the less glamorous side of vuln research, discussing (in mostly laypersons' terms) how we tried in vain to turn a memory corruption bug into full RCE. bishopfox.com/blog/a-crash...

A Crash, Not a Shell: SolarWinds Serve-U CVE-2026-28318

Bishop Fox analyzed CVE-2026-28318, a single-request DoS in SolarWinds Serv-U, chased three RCE paths, and proved each one is a dead end. Patch now.

bishopfox.com

And another one for y’all! This week I published some research into a perfect 10 arbitrary file read affecting Ubiquiti UniFi controller software. I suspect we’ll have more to say about UniFi in the near future… bishopfox.com/blog/looting...

Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557

CVE-2026-22557 is a CVSS 10.0 path traversal in UniFi that lets unauthenticated attackers read controller backups and take over all managed devices.

bishopfox.com

Our blog post on the Arista XSS to RCE chain is now live! We withheld exploit details because the root cause has not been fully mitigated. Patch now if you haven't already, disable your captive portal to reduce the likelihood of exploitation, and stay tuned for new vulns to be disclosed soon!

Arista Firewall XSS to RCE Chain

Arista NG Firewalls: researchers confirm real-world RCE risk and incomplete patches. Learn impact, affected setups, and mitigation steps.

bishopfox.com

Successfully exploited SonicWall CVE-2024-53704, allowing active SSL VPN sessions to be hijacked on affected firewalls. We'll be withholding details for a while because there are still thousands of vulnerable appliances on the public internet.